wp-spec-to-goal

Pass

Audited by Gen Agent Trust Hub on Jul 14, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill generates shell commands for wp-env, WP-CLI, and playwright-cli intended for execution by a downstream agent. This includes the use of wp eval and wp eval-file, which enable dynamic PHP code execution within a containerized WordPress environment.\n- [PROMPT_INJECTION]: The skill contains instructions in AGENTS.md and VERIFY.md advising users or agent harnesses to 'pre-approve or bypass' sandboxes for toolsets like Docker and wp-env. This represents an attempt to influence the security configuration of the execution environment.\n- [PROMPT_INJECTION]: The skill possesses a vulnerability surface for indirect prompt injection (Category 8).\n
  • Ingestion points: Untrusted data enters the context through user-provided 'rough WordPress plugin or feature ideas' as described in SKILL.md.\n
  • Boundary markers: The generated GOAL.md and VERIFY.md templates do not utilize boundary markers or instructions to disregard embedded commands in the interpolated user content.\n
  • Capability inventory: The skill can perform file-write operations (scaffold-templates.md) and generate shell commands for subsequent execution (verify-template.md).\n
  • Sanitization: No evidence of sanitization, validation, or escaping of user-provided content before interpolation into templates was found.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 14, 2026, 09:39 AM
Security Audit — agent-trust-hub — wp-spec-to-goal